CVE-2023-4479: Stored XSS Vulnerability in M-Files Web

DESCRIPTION:

Stored XSS Vulnerability in M-Files Web versions before 23.08 allows attacker to execute script on users browser via stored HTML document within limited time period.

AFFECTED PRODUCTS:

M-Files Web before 23.8

MORE INFORMATION:

Exploiting this vulnerability requires access to M-Files Vault to store malicious HTML files and then requires getting a user to open it with specifically provided link. Normally opening the file from the Vault from M-Files Web would not trigger the vulnerability. Time period for successful attempt is also limited.

CVSS 3.1 Base Score: 7.3

CVSS 3.1 Temporal Score: 6.4

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

CWE: CWE-79 Cross-Site Scripting

CAPEC: CAPEC-592 Stored XSS

Internal ID: 167872

Date issued: 2023-08-22

EXPLOITABILITY

Publicly disclosed: No

Exploited: No

Probability of exploitation: low - responsibly reported

LINKS

https://www.cve.org/CVERecord?id=CVE-2023-4479

HISTORY

2024-03-04 Published